turbot/docker_compliance
GitHub
Loading controls...

Control: 5.23 Ensure that docker exec commands are not used with the privileged option

Description

You should not use docker exec with the --privileged option

Using the --privileged option in docker exec commands gives extended Linux capabilities to the command. This could potentially be an insecure practice, particularly when you are running containers with reduced capabilities or with enhanced restrictions.

Remediation

You should not use the --privileged option in docker exec commands

Default Value

By default, the docker exec command runs without the --privileged option

Usage

Run the control in your terminal:

steampipe check docker_compliance.control.cis_v160_5_23

Snapshot and share results via Steampipe Cloud:

steampipe login
steampipe check --share docker_compliance.control.cis_v160_5_23

SQL

This control uses a named query:

exec_docker_exec_command_no_privilege_option

Tags